PT-2020-6706 · Artifex+6 · Jbig2Dec+6

Published

2020-01-27

·

Updated

2024-08-19

·

CVE-2020-12268

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Artifex jbig2dec versions prior to 0.18
Description The issue is related to a heap-based buffer overflow in the jbig2 image compose function of the jbig2 image.c component in the Jbig2dec decoder. This allows a remote attacker to access confidential data, compromise its integrity, and cause a denial of service.
Recommendations For versions prior to 0.18, update to version 0.18 or later to resolve the issue. As a temporary workaround, consider restricting access to the jbig2 image compose function until a patch is available.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3377
ALT-PU-2020-3413
ALT-PU-2024-11124
BDU:2022-05687
CESA-2020_2897
CVE-2020-12268
DLA-2796-1
MGASA-2020-0213
OPENSUSE-SU-2020:0653-1
OPENSUSE-SU-2020_0653-1
OPENSUSE-SU-2024:10783-1
RHSA-2020:2897
RHSA-2020:2971
RHSA-2020:3043
RHSA-2020_2897
SUSE-SU-2020:1212-1
SUSE-SU-2020:1220-1
SUSE-SU-2020_1212-1
SUSE-SU-2020_1220-1
USN-5405-1

Affected Products

Alt Linux
Astra Linux
Centos
Red Hat
Suse
Ubuntu
Jbig2Dec